Known Vulnerabilities for Custom Post Type UI by Webdevstudios
Listed below are 1 of the newest known vulnerabilities associated with "Custom Post Type UI" by "Webdevstudios".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-96526 json | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of it... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-85410 json | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Ki... | Not Provided | 2026-09-18 | 2026-09-19 |
| CVE-2026-75018 json | The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.1... | Not Provided | 2026-09-05 | 2026-09-07 |
| CVE-2026-66748 json | Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users wit... | Not Provided | 2026-07-28 | 2026-07-31 |
| CVE-2026-18400 json | The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored C... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-16274 json | The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that... | Not Provided | 2026-08-03 | 2026-08-04 |
| CVE-2026-16260 json | The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post ... | Not Provided | 2026-08-22 | 2026-08-23 |
| CVE-2026-15414 json | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-13154 json | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-12995 json | The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i... | Not Provided | 2026-09-22 | 2026-09-22 |